Modders hint at potential kernel exploit hack for Xbox One consoles

xbawks.png

It's been a while since Microsoft released the Xbox One, and despite its age, there haven't been any reliable softmod methods to hack the console. Until now. A post started making the rounds, saying that a method for executing kernel level code on the Xbox One had been found. A list of instructions for preparing Xbox One systems to be hacked was also provided, with the process being as follows:

  1. Ensure your Xbox Live account Login-Type is configured as “No barriers” aka. auto-login with no password prompt
  2. Set your console as “Home Console” for this account
  3. Download the App Game Script
  4. Start the app (to ensure license is downloaded/cached)
  5. Take your console offline! To make extra sure it cannot reach the internet, set a manual primary DNS address of 127.0.0.1
  6. Get a device/microcontroller that can simulate a Keyboard (rubber ducky or similar) - otherwise you have to type a lot manually :D

This method appears to use a UWP app called Game Script on the Xbox One to execute the code, and was discovered by a user named carrot_c4k3. It seems as though the hack will require a lot of manual typing, unless you have a device that can simulate a keyboard, according to the preparation instructions. Reportedly, the latest firmware update for the Xbox One has already patched the exploit out, with the last exploitable firmware being 10.0.25398.4478.

:arrow: Source
:arrow: Video guide on how to prepare your system
:arrow: Proof of concept code
 
Last edited by HellGhast,
Why would they give instructions rn???
Because the way Xbox is set up most users get auto updates once a month, so we're in a limited window between grabbing the requisite app and getting an update next time we go online (and you might need to set your console up as a home console for this to work, which probably leaves some sort of flag on the system before going offline)
 
  • Like
Reactions: btjunior
Im sure my X-one wont connect to anything since I haven't used it in like 5 yrs lol. Plus i'm using a different ISP now. Interested to try this out.
 
  • Like
Reactions: orangy57
Damn, it's probably too late for most folks who still use their XB1 since their console is probably still connected online...
 
Im sure my X-one wont connect to anything since I haven't used it in like 5 yrs lol. Plus i'm using a different ISP now. Interested to try this out.

Keep in mind you need to download the Game Script app before this is patched, or the app is removed from the Microsoft Store. Which means you have a limited time to update the console, download the app, then keep it offline.
 
Keep in mind you need to download the Game Script app before this is patched, or the app is removed from the Microsoft Store. Which means you have a limited time to update the console, download the app, then keep it offline.
oof I have to get it out of my shed once the sun rises. But yeah looks like I will have to pray the update doesn't patch out till then.
 
Might be worth creating a new account to download this and delete any 'good' accounts.

I won't be surprised if MS flags any accounts/consoles which downloads this app, even if they don't immediately ban them.
 
  • Like
Reactions: CoolMe and BigOnYa
I should've put inb4 Chary on my user submitted news post lol

Anyway I'm not getting all that excited about this over the following reasons
-We don't know it's full capability (true for any new exploit)
-m$ can update this at any time.
-No up to date archive of recent firmwares with this exploit (unlike Playstation where you can easily find a specific firmware)
-90% of what Xbox has is ported to PC

What would make me excited for this exploit
-Ability to finally go online with current Gen hardware
-Ability for source code to be rewritten for upgradeable internal storage

Of course all the other bells and whistles this exploit may bring; back ups, emulation, ftp, custom themes submitted by users etc...

This exploit is simply adding pepper and salt to your food as of right now.
 
The Xbox One X is likely to be the most powerful (truly) hackable console for some time. I wouldn't dismiss it out of hand.
The issue being, what if it's the only main console you currently use? Are you going to loose out and not play with friends over a hack that doesn't currently really do anything? Or go out and buy a secondary one and update it immediately and hope that Microsoft hasnt already patched it?
 
  • Haha
Reactions: ChibiMofo
@Chary Worth updating the story with this: The firmware is still okay, but there's an Xbox Insider build some people are getting. If you leave the Insider program, the version returns to the golden 10.0.25398.4478.
Source:
Screenshot_20240610-191605.png


EDIT: I checked my console (not in Insider program, updated right as this post came out) and I'm on the right fw.
 
Last edited by Darth Meteos,
@Chary Worth updating the story with this: The firmware is still okay, but there's an Xbox Insider build some people are getting. If you leave the Insider program, the version returns to the golden 10.0.25398.4478.
Source: View attachment 441578

EDIT: I checked my console (not in Insider program, updated right as this post came out) and I'm on the right fw.
Yeah, when I first updated my One X today it was on 10.0.25398.4908, then I left the insider program and deleted the account from my console, rebooted and it prompted me to update again. After that I was on 10.0.25398.4478. Deleting the account with Xbox Insider from the console and rebooting might be enough, not sure.

I didn't even realise my account was in Xbox Insider anyway, no great loss to leave it. 10.0.25398.4908 might be ok anyway for all I know.
 
  • Like
Reactions: Darth Meteos

Site & Scene News

Popular threads in this forum